11 of 11 people found the following review helpful:
5.0 out of 5 stars
Security explained in a concise, easy-to-read fashion, 18 July 2001
By chicag097 - Published on Amazon.com
This review is from: Surviving Security: How to Integrate People, Process and Technology (Sams white book) (Paperback)
I am the network manager at a mid-size Chicago company and have been tasked with the job of developing a formal security infrastructure for our organization. I have read many of Mandy's InfoWorld articles and eagerly awaited the release of this book. Needless to say, I was not disappointed. Surviving Security is a great resource for understanding the components of a security infrastructure, how they fit together, and how to analyze and select the best approach for your environment. She covers all the basics (security policies, firewalls, IDS, remote access, OS hardening, network architecture, etc.)
In addition, there's a great chapter on authentication techniques. She also discusses the issues most people forget or do not really think about until it is too late: keeping up-to-date with patches, monitoring systems and logs, creating incident response teams, developing secure applications, etc. Most sections have "For More Information" boxes that give resources (books, websites, etc.) where you can go for more detailed information. I thought these were a great feature. She provides insightful information and commentary based on her experiences and then refers you to places where you can find more information. This book does not try to be all things for all people.
The companion website is a great way to keep the content up-to-date. As long as the author keeps the information and links current, this will be a good resource for security information. The product reviews give an independent, third-party opinion that is sometimes hard to find.
For those looking to develop a complete security infrastructure, this is the book to read. Surviving Security gives you an excellent "big picture" look at security that I have found lacking in other security books I have looked at.
10 of 10 people found the following review helpful:
5.0 out of 5 stars
Mandatory Book For The Security Professional, 22 Nov 2001
By James W. S. Ludwig, CISSP - Published on Amazon.com
This review is from: Surviving Security: How to Integrate People, Process and Technology (Sams white book) (Paperback)
I have been an information assurance professional for over 40-years. This is the only book that ties it all together and provides so many additonal bonuses that you cannot go wrong for the price.
What I found best about the book:
1. Great price for all the pertinent and up-to-date information, including references and URL's,
2. Complete, concise, focused; no wandering down memory lane,
3. A great study reference guide in preparation for the CISSP examination (I used it, I took the exam, I am now certified as an Information System Security Professional),
4. The book will be a solid reference for years to come,
5. The author knows her subject and presents it in such a logical manner that it is impossible not to grasp the concepts presented.
6. Can use the author's web site for this book so that you maintain your currency (who else offers this?),
7. If your on the security profession career path this book is mandatory, and
8. Where in the hell (heck) was this book 10-15 years ago.
8 of 9 people found the following review helpful:
4.0 out of 5 stars
Great for someone needing thorough intro info sec, 15 Aug 2001
By Ben Rothke "Author of 'Computer Security: 20 ... - Published on Amazon.com
This review is from: Surviving Security: How to Integrate People, Process and Technology (Sams white book) (Paperback)
Surviving Security is a really good book for someone needing a thorough introduction to information security.
The book covers all of the most important security technologies and processes. After completing the book, the reader will come out with a good understanding the components of an information systems security infrastructure.
All of the chapters contain loads of valuable information. Two extremely valuable sections are (Page 358) Sample Audit Checklist and (Page 399) Assessing Your Needs.
The Sample Audit Checklist contains over 30 pages of technology items that require security. Assessing Your Needs details all of the items required for an effective incident response team....
For those people needing an effective and easily readable reference about computer security, Surviving Security is an excellent resource.